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AMENDMENTS TO THE CLAIMS 
Amended claims follow: 

1 . (Previously Presented) A method for preventing writes to critical files, 
comprising: 

identifying factors associated with a computer; 

monitoring requests to write to files on the computer; and 

conditionally preventing the writes to the files on the computer based on the 
factors to prevent virus proliferation; 

wherein the factors are altered based on the monitoring of the requests to write to 
the files on the computer; 

wherein the factors are updated based on the requests; 

wherein if one of the requests is initiated by an application that is not one of a 
plurality of trusted applications, a user is alerted and allowed to at least one of prevent 
and permit the request initiated by the application. 

2. (Previously Presented) The method as recited in claim 1 , wherein the factors are 
selected from the group consisting of critical files, critical file locations, and the plurality 
of trusted applications. 

3. (Original) The method as recited in claim 1 , wherein the factors are user 
configurable. 

4. (Original) The method as recited in claim I , wherein the factors are identified in a 
registry. 

5. (Original) The method as recited in claim 2, wherein the factors include critical 
files associated with an operating system of the computer. 
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6. (Original) The method as recited in claim 2, wherein the factors include critical 
file locations associated with an operating system of the computer. 

7. (Original) The method as recited in claim 6, wherein the critical file locations 
include folders. 

8. (Previously Presented) The method as recited in claim 2, wherein the factors 
include the plurality of trusted applications that initiate the requests. 

9. (Original) The method as recited in claim I, wherein the factors are updated based 
on a user request. 

10. (Original) The method as recited in claim 1, wherein the factors are updated from 
a remote location via a network. 

11. (Cancelled) 

12. (Original) The method as recited in claim 1 , and further comprising conditionally 
preventing the writes to the files on the computer based on a user confirmation. 

13. (Original) The method as recited in claim 1 2, wherein the factors are updated 
based on the user confirmation. 

14-27. (Cancelled) 

28. (Previously Presented) A method for preventing writes to critical files, 
comprising: 

identifying an operating system associated with a computer; 
looking up at least one of critical files and critical file locations associated with 
the operating system; and 
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preventing access to the at least one of critical files and critical file locations 
associated with the operating system to prevent virus proliferation; 

wherein the at least one of critical files and critical file locations are looked up 
based on requests to write to the at least one of critical files and critical file locations on 
the computer; 

wherein if one of the requests is initiated by an application that is not one of a 
plurality of trusted applications, a user is alerted and allowed to at least one of prevent 
and permit the request initiated by the application. 

29. (Cancelled) 

30. (Previously Presented) The method as recited in claim 1 , wherein the factors 
include a list of cri tical files such that the li st of critical files is updated based on the 
requests. *■ 

3 1 . (Previously Presented) A method, comprising: 
identifying factors associated with a computer; 
monitoring requests to write to files on the computer; and 
conditionally preventing the writes to the files on the computer based on the 

factors to prevent virus proliferation; 

wherein the factors are altered based on the monitoring of the requests to write to 
the files on the computer, 

wherein the factors are updated based on the requests; 

wherein the factors include trusted applications that initiate the requests; 

wherein if one of the requests is initiated by an application that is not one of the 
trusted applications, a user is alerted and allowed to at least one of prevent and permit the 
request initiated by the application. 



